Vulnerability Report: GO-2023-2333
- GHSA-rjjm-x32p-m3f7
- Affects: github.com/consensys/gnark
- Published: Nov 15, 2023
- Modified: May 20, 2024
Range checker gadget allows wider inputs than allowed in github.com/consensys/gnark
For detailed information about this vulnerability, visit https://github.com/Consensys/gnark/security/advisories/GHSA-rjjm-x32p-m3f7.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.9.2-0.20231110170422-f528807119e9
3 unexported affected symbols
- commitChecker.commit
- nbPLONKConstraints
- nbR1CSConstraints
Aliases
References
- https://github.com/Consensys/gnark/security/advisories/GHSA-rjjm-x32p-m3f7
- https://github.com/Consensys/gnark/issues/897
- https://github.com/Consensys/gnark/commit/f528807119e9443df94b8c01fe8ee65abe3c75d8
- https://vuln.go.dev/ID/GO-2023-2333.json
Credits
- @ultrainstinct30
Feedback
See anything missing or incorrect?
Suggest an edit to this report.